All systems operational · Ormskirk, North West England

90% of Cyber Security Attacks Start With an Email

Nine out of ten cyber attacks begin with an email. Here is why email remains the most effective attack vector and what your business can do to reduce the risk.

Why Email Is Still the Most Common Entry Point

Despite decades of awareness, email remains the starting point for around 90% of cyber attacks. The reason is straightforward: email is the primary communication channel for almost every business, which means every employee with an inbox is a potential target. Attackers do not need to find a technical vulnerability in your systems if they can simply trick a member of staff into clicking a link or opening an attachment.

Email-based attacks have grown more convincing over time. AI tools allow attackers to generate personalised, well-written messages at scale. Spoofed sender addresses, lookalike domains, and stolen branding make fraudulent emails increasingly difficult to distinguish from genuine ones on a quick read.

The Main Threats That Start in the Inbox

Phishing

A phishing email impersonates a trusted source, such as a bank, supplier, or colleague, to trick the recipient into handing over login credentials or clicking a malicious link. The fake login page that follows is designed to capture whatever the user enters. Once credentials are stolen, the attacker has legitimate access to your systems.

Malicious attachments

Emails containing infected attachments, whether Word documents, PDFs, or ZIP files, deliver malware directly to the recipient’s device when opened. Some techniques, such as deliberately corrupted files that Word automatically repairs, are specifically designed to bypass email security filters.

Business email compromise

An attacker impersonates a senior colleague or supplier to request an urgent payment or change of bank details. These attacks rely on urgency and authority rather than technical trickery. They are among the costliest forms of email fraud because the transfer often happens before anyone realises something is wrong.

Ransomware delivery

Many ransomware attacks begin with a phishing email that delivers an initial payload. Once executed, the malware spreads through the network, encrypting files before the attack is detected. The email is the entry point; the ransomware is what causes the damage.

Reducing Your Email Risk

Email filtering and anti-spoofing controls

Properly configured email filtering blocks known malicious senders, scans attachments, and flags messages from domains that are impersonating legitimate businesses. SPF, DKIM, and DMARC records reduce the ability of attackers to spoof your domain and prevent others from spoofing domains you trust.

Multi-factor authentication

MFA means that stolen email credentials alone are not enough to access your accounts. Even if a staff member’s password is captured via phishing, the attacker cannot log in without the second factor.

Staff training

Technical controls reduce the volume of malicious emails that reach your team but they do not eliminate it entirely. Staff who know what to look for, how to verify unexpected requests, and when to report something suspicious provide a critical last line of defence.

Clear payment verification procedures

Business email compromise attacks are stopped by process rather than technology. A simple rule that all payment changes or urgent transfer requests must be confirmed by phone call before being actioned prevents the most common and costly form of email fraud.

B
Blowfish Technology

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.